Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
strcat
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
20 ms
·
241.
▲
by
strcat
1y ago
They're referring to the leaky network toggles in LineageOS for different kinds of networks. GrapheneOS won't include that because it doesn't work correctly and gives people the false impression that it's going to stop a
242.
▲
by
strcat
1y ago
> LineageOS can have that, at the owner's preference. Graphene explicitly forbids it. That's not true. You can use apps like RethinkDNS providing local monitoring and filtering of connections while still supporting using a VPN
243.
▲
by
strcat
1y ago
Most banking apps work on GrapheneOS. Around 10% ban using any alternate OS, but a small subset of those specifically permit GrapheneOS now in addition to Google certified devices with the stock OS. It's nearly the same permission mode
244.
▲
by
strcat
1y ago
GrapheneOS is partnered with a major Android OEM and working towards some of their future devices meeting our requirements and providing official GrapheneOS support. It won't be the main operating system, but it will be an officially s
245.
▲
by
strcat
1y ago
You have it backwards. It's smartphones other than iPhones and Pixels with the front door open due to lack of basic security patches and protections. You're making unsubstantiated claims about backdoors not backed by any evidence.
246.
▲
by
strcat
1y ago
They're talking about devices known to be extraordinarily insecure, which are still closed source hardware with closed source firmware. Having schematics for the board does not avoid trusting the hardware. It's still a closed sour
247.
▲
by
strcat
1y ago
Open schematics for a PCB don't make it any harder to hide a backdoor. You're talking about devices which still have an entirely closed source SoC with all of the real complexity. The products you're repeatedly marketing here
248.
▲
by
strcat
1y ago
GrapheneOS is partnered with a major Android OEM we're working with towards their next generation devices supporting GrapheneOS. The devices will meet all of our official requirements listed at https://grapheneos.org/fa
249.
▲
by
strcat
1y ago
GrapheneOS provides a lot of features not available in LineageOS. Our focus for is privacy, security and replacing Google apps/services. The features we add aren't only privacy and security features. We provide our own network loc
250.
▲
by
strcat
1y ago
GrapheneOS is a privacy and security hardened OS. The third party comparison table at https://eylenburg.github.io/android_comparison.htm focused on privacy and security provides a good overview. The GrapheneOS features page
251.
▲
by
strcat
1y ago
We have the sources for the patches which is how they get applied the source tree. We have both the regular releases and security preview releases so it's easy to see what was changed since it's a small amount of code: currently 5
252.
▲
by
strcat
1y ago
The preview patches are source code patches we're applying to the source tree used for the regular GrapheneOS releases. We have the sources for the patches, but we need to wait to the embargo end date to publish the security preview pa
253.
▲
by
strcat
1y ago
No, GrapheneOS is partnered with a major Android OEM and has security partner access through them. Our security preview releases are in full compliance with the terms set by Google. It's permitted to ship the patches early with delayed
254.
▲
by
strcat
1y ago
Only a tiny subset of apps ban GrapheneOS. Several such as Swissquote recently decided to permit it via hardware attestation. Swizerland's government ID app is also going to be permitting it. We're working on getting more apps usi
255.
▲
by
strcat
1y ago
Just make sure it's an unlocked device. Pixel 8+ is recommended due to 7 years of support from launch and hardware memory tagging. A used Pixel 8 or Pixel 8a is a great option. 6th and 7th generation Pixels are fine, but they launched
256.
▲
by
strcat
1y ago
There's a difference between Apple doing good integration of MTE and the work they're doing being truly novel. ARM MTE is not the only memory tagging implementation. Apple getting ARM to add something many people have wanted from
257.
▲
by
strcat
1y ago
MTE is also available on a bunch of non-Pixel devices we can't support or which don't meet our other requirements. 8th/9th generation Pixels are half of the devices we support. 7 years of support is the status quo but it was
258.
▲
by
strcat
1y ago
I disagree with corporations marketing misrepresenting their security capabilities to sell more devices and services. Apple and Google are much better at security than most tech companies but definitely nowhere near as successful as Apple&#
259.
▲
by
strcat
1y ago
It's available since October 2023 when it launched on the Pixel 8. We integrated it into hardened_malloc that month and deployed it in production. We've been working on further research and improvements based on MTE since then. Gr
260.
▲
by
strcat
1y ago
> My impression is that Apple's threat intelligence effort is similar in quality to Google's. We have a lot of direct experience with Google not having much of a clue about how their own devices are being exploited in the wild.
261.
▲
by
strcat
1y ago
There are widely available tools for exploiting iPhones. These are available to low level law enforcement, border guards, etc. They're often abused. The same goes for remote exploits. Apple and Google have succeeded in making the explo
262.
▲
by
strcat
1y ago
Your claims about the conversation are based on Rossmann's lies about what was said and his lies about the context for it. He was and still is actively and openly engaging in bullying, libel and harassment. You're not even being s
263.
▲
by
strcat
1y ago
Xen itself is a microkernel. The list of vulnerabilities you've linked has a very limited scope not accounting for most vulnerabilities impacting QubesOS users. It also isn't a complete list for that limited scope. However, what y
264.
▲
by
strcat
1y ago
No, it's not wrong. Their OS objectively does not provide firmware updates and they've blocked updating SoC firmware. The section you've linked acknowledges that they're blocking updating firmware for the SoC. It states
265.
▲
by
strcat
1y ago
https://news.ycombinator.com/item?id=45309658
266.
▲
by
strcat
1y ago
Both, but first adding official support for using Google Messages.
267.
▲
by
strcat
1y ago
Other web servers have a reliable implementation of OCSP stapling via their support for loading the OCSP response from an external file. It isn't as convenient as having it built-in but it works well. GrapheneOS used https://
268.
▲
by
strcat
1y ago
> You are a partisan. I provided accurate and verifiable information. You are yourself clearly here to promote /e/ and attack GrapheneOS, which you're doing with objectively false claims about both. /e/ has far l
269.
▲
by
strcat
1y ago
This post ignored the vast majority of what was said and gave very inaccurate and misleading responses to the rest. There are even many responses in their own forum to that post and others debunking the claims. Beyond the privacy and securi
270.
▲
by
strcat
1y ago
> My only concern is this: Android phones I tried to root so far will be "tainted" if I unlock the bootloader and can never go back to a state where it passes all checks. There's no such thing for Pixels, and it also doesn
More ›